New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[WIP] [libOS] Single Process lifetime rollback protection for Protected Files #1856
Draft
g2flyer
wants to merge
11
commits into
gramineproject:master
Choose a base branch
from
g2flyer:msteiner/enclave-lifetime-rollback-protection
base: master
Could not load branches
Branch not found: {{ refName }}
Could not load tags
Nothing to show
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
[WIP] [libOS] Single Process lifetime rollback protection for Protected Files #1856
g2flyer
wants to merge
11
commits into
gramineproject:master
from
g2flyer:msteiner/enclave-lifetime-rollback-protection
+799
−166
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
from
April 23, 2024 04:51
2233cf6
to
f42b179
Compare
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
from
May 6, 2024 15:36
11858ac
to
79890bf
Compare
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
from
May 10, 2024 22:53
79890bf
to
95c577f
Compare
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
from
May 20, 2024 19:10
95c577f
to
86f99d0
Compare
This is conceptually similar to the commit "[LibOS] Fix `ENOENT` error in `fchmod` on unlinked file". Three new LibOS regression sub-tests are added. Co-authored-by: g2flyer <michael.steiner@intel.com> Signed-off-by: g2flyer <michael.steiner@intel.com> Signed-off-by: Dmitrii Kuvaiskii <dmitrii.kuvaiskii@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
[LibOS] Fix dentry of open files after rename Signed-off-by: g2flyer <michael.steiner@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
Signed-off-by: g2flyer <michael.steiner@intel.com>
…es (WIP) * adds libos_encrypted_volume as mount-data for protected fileystem which includes map <name, <last-root-hash, ...>> to keep track of root hashes across open/close cycles of a particular value, ensuring consistency across the whole enclave life-time Signed-off-by: g2flyer <michael.steiner@intel.com>
…ted files (WIP) Signed-off-by: g2flyer <michael.steiner@intel.com>
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
2 times, most recently
from
May 22, 2024 23:50
a8b5d10
to
ee4c0c4
Compare
…ted files (WIP) Signed-off-by: g2flyer <michael.steiner@intel.com>
g2flyer
force-pushed
the
msteiner/enclave-lifetime-rollback-protection
branch
from
May 23, 2024 18:08
ee4c0c4
to
17d0062
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of the changes
This is a WIP PR addresses issue #1835, i.e., rollback protection of protected files beyond a single open-to-close window but across the whole runtime of gramine. Released as draft PR in anticipation of 23. April 2024 Community Call. It depends on closing PR #1874 and PR #1875 (and is currently rebased on the current version of these to work)
Steps:
How to test this PR?
This change is